Job Title: Third Party Technology Risk Management Analyst / Consultant
Department: ITG CDF Germany
About Business line/Function: CDF – Germany is a unit which makes sure that CISO key objectives are in line with Group strategy.
Position Purpose:
The role of the Third-Party Technology Risk Management Analyst / Consultant is to implement the set of operational activities to be carried out within BNP Paribas (Group & entities) to manage ICT & Cyber risks for the beneficiaries of sourcing (Outsourcing, purchasing & shoring) initiatives supported by ICT service providers and third parties involved in ICT projects or business projects with ICT components. Resource can operate within TPTRM scope governance, providers, beneficiaries & SMEs spread throughout global region. As part of this role, Resource will have to work closely with German stakeholders. Especially, Resource will help clients assess the risks associated to their arrangement and provide recommendations for managing those risks.
Responsibilities
Direct Responsibilities
· Instruct the 5 European Bank Authority ICT risks categories and to follow them throughout TPTRM assessments
· Define the applicable contractual ICT security requirements to the use case to protect confidentiality, integrity and availability of Beneficiary data and systems
· Perform third-party technology risk assessments to help beneficiaries/contract owners identify and evaluate complex business and technology risks related to their third parties, and provide recommendations for managing those risks
· Provide periodic status updates including potential risks and delays to the project delivery to beneficiary project manager, conduct workshops wherever necessary
· Assist in the selection and tailoring of third-party technology risk management approaches, methods and tools to support delivery of third-party cyber risk assessment services
· Review thoroughly Asset classifications and pre-existing asset related risks & control responses ensuring sync with TPTRM assessments responses
· Identify key actors for decision making according to flagged risk families
· Select the requirements to include in the specific ICT due diligence questionnaire and communicate them to the shortlisted suppliers
· List of the risks that should be formalized in a risk management plan given the third party's answers and report of the third party's ability to manage risks
· Accompany the beneficiary for logging information in the various Group arrangements register
· Analyze and score the collected supplier information of the shortlisted suppliers.
· Support P&P / Beneficiary team in the negotiation of the ICT clauses and security annex with the Provider security team
· Each performance of the Service may be considered as independent from the others, and the results of the services to be recorded under the GRC Register (ServiceNow, OP 360 etc)
· Apply group key procedures, templates, to carry out risk’s activities
· Ensure to highlight key factors using Risk Assessment Form that will help SMEs in decision making
· Coordinate the activities of IT and non-IT stakeholders (Outsourcing coordinators, Supplier Risk, Buyers, LoD2, CISO, ITRO, …) with regards to the monitoring of ICT Third Party providers
· Ensure periodic review of Arrangements & contracted ICT services
· Demonstrate knowledge in one or more of the following cyber risk domains, including: Security Governance and Management, Security Policies and Procedures, Application Security Controls, Access Controls, Network Security Operations, Security Architectures, Identity Management, Disaster Recovery & Business Continuity, Incident Response, Risk Management, Privacy and Data Protection, Encryption.
· Participate in Initialization Committee/ Validation Committee & Go-Live committee for Supporting specific arrangements and results
Technical & Behavioral Competencies
· Functional Skills
o Experience in IT Risk and Cyber Security domains in a financial institution demonstrating a high-level of commitment and self-motivation.
o Experience in the Finance & IT industry with strong exposure to IT Operations, Application Security, and/or network administration, IPS
o Strong demonstrated knowledge of Risk & Compliance, cybersecurity, cyber risk, cyber threats, Third Party Technology Risk Management/ Vendor assessments
o Risk knowledge and awareness of risks combined with enthusiasm and a genuine interest in the role of Risk Assessment, Third Party Technology Risk Assessment, Risk Analysis in business and providing Risk Opinion as a subject matter expert.
o Working knowledge of global regulations, frameworks and standards(ISO, NIST, COBIT, PCI-DSS, HIPAA) and conversant in the tactics, techniques and procedures used by Risk adversaries.
o Demonstrates a calm professional approach, with a good understanding of delivery within time constraints and the need to escalate/inform departmental management as appropriate.
o IT knowledge
· Technical Skills:
o Good understanding of organizations and IT Businesses
o Good technical understanding of infrastructures and IT Security Productions and Systems
o IT risk /Third Party risk analysis and management methods and should have worked on Risk Management Tools like, ServiceNow etc.
o Knowledge of Cyber Resilience, IT continuity and business continuity
o GRC - Governance, Risk Management and Compliance Management.
o Firewall and Internet technologies; Cloud Security, Banking Tools & Technologies.
o Secure access control mechanisms; Encryption and Key management technics
· Behavioral Skills:
o Strong Communication, Analytical and problem-solving skills.
o Proven organizational skills with excellent multi-tasking, result oriented and prioritization skills
o Good documentation and reporting skills
o Ability to work independently
o Strong communication and interpersonal skills, able to communicate and relate easily with IT, Finance and back-office users
o Good communication, technical writing/diagramming skills
o Attention to detail and accuracy
o Capacity for creativity and innovation
o Self-discipline
Specific Qualifications:
· One or more Industry-recognized information Security certifications such as CISSP, CISA, GCCC, CISM, CEH, CRISC, OSCP or Security+.
· IT Security tools like Firewalls, IPS, WAF, Endpoint protection, Network security, etc.
· IT Auditing (ISO27001/2, NIST 800 Series, ISO27005, ISO42001)
· Regulatory Compliance
Skills Referential (Required knowledge, skills and abilities)
Behavioral Skills:
· Communication skills - oral & written
· Attention to detail / rigor
· Ability to deliver / Results driven
· Creativity & Innovation / Problem solving
Transversal Skills:
· Analytical Ability
· Ability to manage a project
· Ability to understand, explain and support change
· Ability to develop and adapt a process
· Ability to anticipate business / strategic evolution
Education Level: Bachelor’s degree or equivalent with at least 5 years of experience.
Location: Bangalore
About BNP Paribas Group:
BNP Paribas is the European Union’s leading bank and key player in international banking. It operates in 65 countries and has nearly 185,000 employees, including more than 145,000 in Europe. The Group has key positions in its three main fields of activity: Commercial, Personal Banking & Services for the Group’s commercial & personal banking and several specialized businesses including BNP Paribas Personal Finance and Arval; Investment & Protection Services for savings, investment, and protection solutions; and Corporate & Institutional Banking, focused on corporate and institutional clients. Based on its strong diversified and integrated model, the Group helps all its clients (individuals, community associations, entrepreneurs, SMEs, corporates and institutional clients) to realize their projects through solutions spanning financing, investment, savings and protection insurance. In Europe, BNP Paribas has four domestic markets: Belgium, France, Italy, and Luxembourg. The Group is rolling out its integrated commercial & personal banking model across several Mediterranean countries, Turkey, and Eastern Europe. As a key player in international banking, the Group has leading platforms and business lines in Europe, a strong presence in the Americas as well as a solid and fast-growing business in Asia-Pacific. BNP Paribas has implemented a Corporate Social Responsibility approach in all its activities, enabling it to contribute to the construction of a sustainable future, while ensuring the Group's performance and stability.
About BNP Paribas India Solutions:
Established in 2005, BNP Paribas India Solutions is a wholly owned subsidiary of BNP Paribas SA, European Union’s leading bank with an international reach. With delivery centers located in Bengaluru, Chennai and Mumbai, we are a 24x7 global delivery center. India Solutions services three business lines: Corporate and Institutional Banking, Investment Solutions and Retail Banking for BNP Paribas across the Group. Driving innovation and growth, we are harnessing the potential of over 10000 employees, to provide support and develop best-in-class solutions.
Commitment to Diversity and Inclusion
At BNP Paribas, we passionately embrace diversity and are committed to fostering an inclusive workplace where all employees are valued, respected and can bring their authentic selves to work. We prohibit Discrimination and Harassment of any kind and our policies promote equal employment opportunity for all employees and applicants, irrespective of, but not limited to their gender, gender identity, sex, sexual orientation, ethnicity, race, colour, national origin, age, religion, social status, mental or physical disabilities, veteran status etc. As a global Bank, we truly believe that inclusion and diversity of our teams is key to our success in serving our clients and the communities we operate in. As a global Bank, we truly believe that inclusion and diversity of our teams is key to our success in serving our clients and the communities we operate in.